[SECURITY] [DSA 4456-1] exim4 security update

From: Salvatore Bonaccorso <carnil@debian.org>
To: bugtraq@securityfocus.com
Cc:
Subject: [SECURITY] [DSA 4456-1] exim4 security update
Date:


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-4456-1                   security@debian.org
https://www.debian.org/security/                     Salvatore Bonaccorso
June 05, 2019                         https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : exim4
CVE ID         : CVE-2019-10149

The Qualys Research Labs reported a flaw in Exim, a mail transport
agent. Improper validation of the recipient address in the
deliver_message() function may result in the execution of arbitrary
commands.

For the stable distribution (stretch), this problem has been fixed in
version 4.89-2+deb9u4.

We recommend that you upgrade your exim4 packages.

For the detailed security status of exim4 please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/exim4

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAlz34D1fFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0QCqxAAlkVHIGImt1pE5N7GjCruh99Wr6RZc4zNomIQg9U1hT7WnVokLb94PTJG
2B2GI+s7jAbF5Uqz+gFgzIAFIDmRS49wSuevFS9lS0UVu8TedsXCVVsWvprqxF3D
w9KSfgQJOVNQybcjx3b3L+xkoUtKDz2vh4tM6k9Gaz1x/HBvynV0vTGIk3V95eeZ
/unZZSEuShNOD4K1IU+CmP7kfbyTL+VL0lPYqRccMXD8SLSjWTtBkA4ZPKtdMM4k
tkxhlj3MGe+9xk7XoFTvZonZHCizC1LyzWjI7HW3aqon641XveYQVfRE+quSOOFq
PnQuMBQjuujmmAVbGXbnZ5AbJocPHkYcDXEdG+VbjhcAOfQjO/maOPs9XjdJdfjF
AiB30SBogrjJpft+Bwy9I4fUde7S70GaYLZdYzWWZWykAVDkecQyr42tlvmAiSic
6AyhQTrLS7q/Y3Uqs49Nd21xTVGL2V402N9gQUHuJwwrODXAwaG1v1J+i3pn7WZN
iGKvME+E/m0T+VpLPsQLePvaef3nPksMgme2uohhHlMqz6rn5bW1emE5LixkKQoP
84bR25vAJwTo3mRIQjtamZ6FQPKhzGoFuCjnH59S6zfJdgqCJc2026xtq3elUl7v
L1dKAGe7nLWBrZrFZD1cTRlRFSHemfHMm34LrXsM+s10IrCM1ZQ=
=frZm
-----END PGP SIGNATURE-----





Copyright © 1995-2019 LinuxRocket.net. All rights reserved.